Users Guide

Table Of Contents
AAA authentication............................................................................................................................................................921
User re-authentication......................................................................................................................................................922
Password strength............................................................................................................................................................922
Simple password check....................................................................................................................................................923
Obscure passwords.......................................................................................................................................................... 923
Role-based access control...............................................................................................................................................924
Assign user role..................................................................................................................................................................924
Bootloader protection.......................................................................................................................................................925
Linuxadmin user configuration.........................................................................................................................................925
AAA authentication........................................................................................................................................................... 926
RADIUS authentication.....................................................................................................................................................927
RADIUS over TLS authentication....................................................................................................................................928
TACACS+ authentication.................................................................................................................................................929
Unknown user role............................................................................................................................................................ 930
SSH server.........................................................................................................................................................................930
Virtual terminal line ACLs.................................................................................................................................................. 931
Restrict SNMP access..................................................................................................................................................... 932
Enable AAA accounting.................................................................................................................................................... 932
Enable user lockout...........................................................................................................................................................932
Limit concurrent login sessions....................................................................................................................................... 933
Enable login statistics........................................................................................................................................................933
Privilege levels .................................................................................................................................................................. 934
Configure privilege levels............................................................................................................................................934
Configure enable password........................................................................................................................................935
Audit log..............................................................................................................................................................................936
Security commands...........................................................................................................................................................937
aaa accounting.............................................................................................................................................................937
aaa authentication login..............................................................................................................................................937
aaa re-authenticate enable........................................................................................................................................ 938
boot protect disable username..................................................................................................................................938
boot protect enable username password.................................................................................................................939
clear logging audit....................................................................................................................................................... 939
crypto ssh-key generate............................................................................................................................................ 939
disable........................................................................................................................................................................... 940
enable............................................................................................................................................................................940
enable password priv-lvl..............................................................................................................................................941
ip access-class..............................................................................................................................................................941
ip radius source-interface...........................................................................................................................................942
ip tacacs source-interface..........................................................................................................................................942
ipv6 access-class.........................................................................................................................................................942
ip ssh server challenge-response-authentication....................................................................................................943
ip ssh server cipher..................................................................................................................................................... 943
ip ssh server enable.....................................................................................................................................................944
ip ssh server hostbased-authentication................................................................................................................... 944
ip ssh server kex..........................................................................................................................................................944
ip ssh server mac.........................................................................................................................................................945
ip ssh server password-authentication.....................................................................................................................946
ip ssh server port.........................................................................................................................................................946
ip ssh server pubkey-authentication.........................................................................................................................947
ip ssh server vrf........................................................................................................................................................... 947
Contents
17